197
Maximum account idle time
You can set the maximum account idle time for user accounts. When an account is idle for this period of
time since the last successful login, the account becomes invalid.
Password not displayed in any form
For security purposes, nothing is displayed when a user enters a password.
Logging
The system logs all successful password changing events and user adding events to the password control
blacklist.
FIPS compliance
The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for features,
commands, and parameters might differ in FIPS mode (see "
") and non-FIPS mode.
Password control configuration task list
The password control features can be configured in several different views, and different views support
different features. The settings configured in different views or for different objects have the following
application ranges:
•
Settings for super passwords apply only to super passwords.
•
Settings in local user view apply only to the password of the local user.
•
Settings in user group view apply to the passwords of the local users in the user group if you do not
configure password policies for these users in local user view.
•
Global settings in system view apply to the passwords of the local users in all user groups if you do
not configure password policies for these users in both local user view and user group view.
For local user passwords, the settings with a smaller application scope have higher priority.
To configure password control, perform the following tasks:
Tasks at a glance
Setting global password control parameters
Setting user group password control parameters
Setting local user password control parameters
Setting super password control parameters